Have Any VPNs Been Hacked or Leaked Data? A Track Record
A VPN's marketing promises are one thing; its actual security track record is another. Some incidents exposed real user data. Others exposed nothing at all — because there were no logs to leak, which is itself a meaningful real-world test of a no-logs claim. Here's a factual rundown of both kinds.
Incidents that exposed real user data
These cases involved actual VPN providers whose practices didn't match their privacy claims:
The common thread: every one of these was a marketing claim that hadn't been independently verified at the time.
- Hola VPN: the free, widely used browser extension was found reselling users' idle bandwidth as exit nodes for a commercial botnet — without clearly disclosing it
- UFO VPN (2020): a free VPN left an unsecured database exposing user logs — including connection timestamps and, in some records, plaintext account passwords — despite advertising a no-logs policy
- IPVanish (2016): despite a no-logs claim, the provider handed a user's connection logs to the FBI. It has since changed ownership and ended that server infrastructure.
Incidents that tested (and passed) no-logs claims
Not every high-profile incident is bad news — some are the strongest evidence a no-logs claim can get:
- NordVPN (2018): a data center hosting one NordVPN server was breached in Finland. Investigators found no user activity logs — because none existed.
- ExpressVPN (2017): Turkish authorities seized a server as part of an investigation. No usable logs were recovered.
- Private Internet Access: has received multiple FBI subpoenas over the years and has never produced user activity data, since none is collected.
What to actually check before trusting a VPN
- An independent audit of the no-logs policy, not just a self-declared claim
- RAM-only (diskless) servers, which can't retain data through a power cycle or seizure
- A track record under real legal or security pressure — audits are a snapshot, incidents are a stress test
- Transparency reports disclosing how many data requests were received and how many were fulfilled
Frequently asked questions
Does one bad incident mean a VPN is unsafe forever?
Not necessarily — ownership, leadership, and infrastructure can change substantially after an incident. Check whether the provider has since been independently audited and whether the underlying issue (e.g. the infrastructure or ownership involved) has changed.
Are free VPNs more likely to have these issues?
Based on the record, yes — most confirmed data-exposure incidents involve free VPN apps, which face more pressure to monetize user data to cover infrastructure costs. See our guide on free vs. paid VPNs for the full picture.
How can I check if a VPN has had a public incident?
Search the provider's name alongside terms like 'data breach,' 'audit,' or 'subpoena.' Independent audit reports (when published) and court records from subpoena cases are the most reliable sources — more reliable than the provider's own marketing pages.